Privacy Policy

Last updated August 26, 2026

GERDMenu helps users scan restaurant menus and compare dishes using visible menu details and their selected caution profile. GERDMenu is informational only and is not medical advice, diagnosis, or treatment.

Information processed

Analytics

Service providers and safeguards

GERDMenu uses Cloudflare to host the backend and cache, OpenAI to analyze menus, and PostHog for optional analytics. We use these providers only under service terms that require them to protect data and limit processing to authorized purposes. GERDMenu requires the same or equivalent protection described in this policy and remains responsible for data they process on our behalf.

Information not collected

Storage and retention

Parsed menu results may be cached by the Cloudflare-hosted backend for up to 7 days to reduce repeated processing. Cache keys may reflect menu content, the pseudonymous device identifier, and selected profile context. Daily abuse and monthly quota windows stop affecting access after the applicable day or month. Short-lived entitlement mirrors expire after the subscription and grace period; pseudonymous quota, purchase-verification, revocation, and replay-prevention records may be retained longer as needed to enforce purchase access and prevent allowance or transaction replay. A pseudonymous lifetime counter is retained to enforce the three free menu scans. If the starter offer is purchased, a server-side record derived from the Apple-signed app transaction identifier retains the one-purchase flag, three-credit grant, remaining credits, and transaction replay protection across reinstalls and devices; this ledger does not expire.

GERDMenu requests OpenAI processing without persistent response storage. Under OpenAI's standard API controls, request content and related abuse-monitoring logs may nevertheless be retained for up to 30 days, or longer when legally required; API content is not used to train OpenAI models unless the API account owner separately opts in.

If analytics is allowed, PostHog analytics events remain in GERDMenu's PostHog project until deleted under the project's retention and deletion controls or in response to a supported deletion request. Turning analytics off stops new events but does not automatically erase events already collected. You may request deletion of associated analytics by emailing us.

Your local scan history remains on your device unless you delete the app. The pseudonymous identifier remains in iCloud Keychain, and the private CloudKit subscription record remains in your iCloud account, until removed through your Apple account/device storage controls or a supported data request.

Contact

For privacy questions or data requests, email casstao@gmail.com. For general help, visit GERDMenu Support.